CVE-2020-35497: Ovirt Ovirt-Engine

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

Affected products

  • Ovirt Ovirt-Engine: up to and including 4.4.3
  • Red Hat Virtualization: version 4.0 only

Published 2020-12-21. Last modified 2026-06-17.